Skip to main content

Synchronize Torq Case Tags to Microsoft Sentinel Incidents - Workflow Template

Synchronize Torq Case Tags to a Sentinel Incident driven by a "Tags Updated" Trigger.

Updated yesterday

The "Synchronize Torq Case Tags to Microsoft Sentinel Incidents" workflow template is designed to enhance case management by ensuring seamless synchronization between Torq case tags and Microsoft Sentinel incidents. When a tag on a Torq case is updated, this workflow automatically updates the associated incident in Microsoft Sentinel with corresponding labels, ensuring accurate and up-to-date incident information. This integration streamlines communication and improves the efficiency of incident tracking and response.

Use Cases

Case Management

Workflow Breakdown

  1. Workflow triggers when a new tag is added or updated.

  2. Fetch Sentinel Incident ID from Case Custom Fields.

  3. Creates a new session on Microsoft Sentinel and updates an incident with the new tags.

Vendors

Utils, Torq Cases, Microsoft Sentinel

Tips

Did this answer your question?